Fixed set for secret scalar

This commit is contained in:
2023-05-15 09:19:48 +02:00
parent d3e1f77e60
commit 4de5dadc5c
5 changed files with 8 additions and 11 deletions

View File

@@ -16,7 +16,7 @@ This section shows that \igame implies the UF-NMA security of the EdDSA signatur
\large
\begin{algorithmic}[1]
\Statex \underline{\game \igame}
\State $a \randomsample \{2^{n-1}, 2^{n-1} + 8, ..., 2^n - 8\}$
\State $a \randomsample \{2^{n-1}, 2^{n-1} + 2^c, ..., 2^n - 2^c\}$
\State $\groupelement{A} \assign a \groupelement{B}$
\State $s^* \randomsample \adversary{A}^{\ioracle(\inp)}(\groupelement{A})$
\State \Return $\exists (\groupelement{R}^*, \ch^*) \in Q: \groupelement{R}^* = 2^c s^* \groupelement{B} - 2^c \ch^* \groupelement{A}$